GHSA-p8gp-2w28-mhwg
CRITICALCVE-2026-23515A Command Injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated users can also exploit this vulnerability if security is disabled on the Signal K server. This occurs due to unsafe construction of shell commands when processing navigation.datetime values receive
- Affected
- < 1.5.0
- Fixed in
- 1.5.0
- Weakness
- CWE-78
- Published
- 2026-02-02
- Source
- github